CWE-89
20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Responsive Events And Movie Ticket Booking Script Project 1Responsive Events And Movie Ticket Booking Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. |
1Multireligion Responsive Matrimonial Project 1Multireligion Responsive Matrimonial May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. |
1Yoga Class Script Project 1Yoga Class Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Yoga Class Script 1.0 has SQL Injection via the /list city parameter. |
1Secure E Commerce Script Project 1Secure E Commerce Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. |
1Responsive Realestate Script Project 1Responsive Realestate Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. |
1Readymade Video Sharing Script Project 1Readymade Video Sharing Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. |
1Readymade Php Classified Script Project 1Readymade Php Classified Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. |
1On Demand Marketplace Script Project 1On Demand Marketplace Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Professional Service Script 1.0 has SQL Injection via the service-list city parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. |
1Opensource Classified Ads Script Project 1Opensource Classified Ads Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. |
1Online Exam Test Application Script Project 1Online Exam Test Application Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. |
1Multivendor Penny Auction Clone Script Project 1Multivendor Penny Auction Clone Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. |
1Lawyer Search Script Project 1Lawyer Search Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. |
1Laundry Booking Script Project 1Laundry Booking Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. |
1Kickstarter Clone Script Project 1Kickstarter Clone Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. |
1Foodspotting Clone Script Project 1Foodspotting Clone Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. |
1Event Calendar Category Script Project 1Event Calendar Category Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Event Search Script 1.0 has SQL Injection via the /event-list city parameter. |
1Facebook Clone Script Project 1Facebook Clone Script May 13, 2026 Dec 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter. |
1Hotel Restaurant Reviews And Feedback Script Project 1Hotel Restaurant Reviews And Feedback Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Food Order Script 1.0 has SQL Injection via the /list city parameter. |
1Freelance Website Script Project 1Freelance Website Script May 13, 2026 Dec 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. |